Latest Update 2026 | Pass Certification Exam
1. What does CVSS stand for in the context of vulnerability management?
Comprehensive Vulnerability Scoring System
Common Vulnerability Scoring System
Critical Vulnerability Security Standard
Common Virus Scanning System
2. What is one advantage of active scanning in vulnerability management?
Active scanning is less intrusive than passive scanning.
Active scanning does not require network access.
Active scanning requires less time to implement.
Active scanning can accelerate the collection of data.
3. If a company relies heavily on open-source libraries for its software
development, what strategy should it implement to mitigate the associated
vulnerabilities?
Regularly monitor and update the libraries for security patches
Rely solely on proprietary software for all development
Avoid using any open-source libraries altogether
Limit the use of libraries to only those with a single owner
4. Which of the following is commonly done as part of a vulnerability scan?
Cracking employee passwords
Identifying unpatched workstations
, Exploiting misconfigured applications
Sending phishing emails to employees
5. Describe how OSINT contributes to the creation of cybersecurity threat
maps.
OSINT is a method for encrypting sensitive data.
OSINT provides publicly available information that helps identify
and visualize potential cyber threats.
OSINT is a proprietary tool used for scanning vulnerabilities.
OSINT focuses solely on internal network security.
6. If an organization decides to share threat intelligence with its partners, what
is a potential outcome of this decision?
Higher costs associated with threat intelligence
Increased vulnerability to attacks due to shared data
Enhanced collaborative defense against cyber threats
Decreased awareness of emerging threats
7. Why might continuous vulnerability scanning be considered impractical for
some organizations?
Continuous vulnerability scanning is always necessary for all systems.
Continuous vulnerability scanning can be impractical due to high
costs and resource allocation issues.
Continuous vulnerability scanning does not provide valuable insights.
Continuous vulnerability scanning is only relevant for large
organizations.
, 8. What action should be taken immediately after selecting a vulnerability
scanning tool?
Install additional software
Update the plug-ins
Review the user manual
Conduct a system scan
9. What is the Common Vulnerability Scoring System (CVSS)?
A scoring system for exploits.
A scoring method that conveys vulnerability severity and helps
determine the urgency and priority of response.
A vulnerability-mitigation risk analysis tool.
A tool to automatically mitigate vulnerabilities.
10. What is an organization's largest security risk when it comes to using open
source applications?
The source code is visible by anyone in the world.
The operations department does not install version updates and
patches in a timely manner.
The creator(s) of the application may not have used secure
software development procedures.
The creator(s) decide to discontinue further development of the
application.
11. Discuss how the lack of ownership and control over open-source libraries
contributes to their vulnerability.